Skip to main content

Assert the SSOT principle for users and groups across disparate applications and services.

Project description

User Lifecycle Management

lifecycle is a piece of software intended to help implement the Single Source of Truth principle across disparate applications and services. It is intended to be used alongside a single-sign-on authentication system such as SAML or OIDC, and provide lifecycle management for the users in these applications.

Why?

Some software we use doesn't have good user lifecycle management. While we can use SSO to log into these pieces of software, we end up with ghost users, manual user and role management, and worse of all, users with non-sso authentication methods.

How?

The application is intended to be run in an automated scheduled fashion. A docker container will be provided where a config volume can be mounted to configure your applications.

Layout

A typical workflow for lifecycle will have one source, such as LDAP or a CSV file, and multiple targets, such as Google Apps or SuiteCRM. The entire user and group list will be extracted from the source, and used to set up the target in a matching way. This can include adding and removing users, changing contact details and disabling user accounts.

Ideally if a target has an access-level system thats vaguely sensible, we can manage a user's access too - a target will manage roles within its application, and make sure users are in the correct roles as specified in source

User Stories

User Creation

  1. Alice starts at company, and has an LDAP account created for them by Bob.
  2. When lifecycle is next run, it pulls Alice's account details from LDAP, and uses them to create a matching user for them in SuiteCRM.
  3. Alice is able to log into SuiteCRM immediately via SAML, and has the correct permissions and access.

User Disablement

  1. Charlie decides to move on from company, and on their final day their LDAP account is disabled.
  2. When lifecycle is next run, it notices Charlie's LDAP account is disabled, and disables their SuiteCRM access.
  3. Charlie is no longer able to authenticate to SuiteCRM, and they no longer show up as a valid user for other SuiteCRM users.

User Access Change

  1. David moves from the engineering department to the sales department, and is added to the sales group
  2. When lifecycle is next run, it will modify David's roles to give them access to sales specific functionality within SuiteCRM.
  3. David is able to log into SuiteCRM and has correct access.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ct_lifecycle-0.1.4.tar.gz (36.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ct_lifecycle-0.1.4-py3-none-any.whl (18.8 kB view details)

Uploaded Python 3

File details

Details for the file ct_lifecycle-0.1.4.tar.gz.

File metadata

  • Download URL: ct_lifecycle-0.1.4.tar.gz
  • Upload date:
  • Size: 36.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.11.7

File hashes

Hashes for ct_lifecycle-0.1.4.tar.gz
Algorithm Hash digest
SHA256 225a4d414ae43a87bc4417ef6c37887a3617c07a479f45874c23cde2d4a004e7
MD5 f5d0fe37b04927acc25eb02e69268c22
BLAKE2b-256 488fdceccafcece054ad67516b3e6065fe0f2eac590405f8223e846c11e3bc6d

See more details on using hashes here.

File details

Details for the file ct_lifecycle-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: ct_lifecycle-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 18.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.11.7

File hashes

Hashes for ct_lifecycle-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 a4a36bd784a48e6c3a5f73419712165f370f78b6b1b95a7cd70529eaf18a1d51
MD5 111c407f44ac5829298583eb34a6d365
BLAKE2b-256 15a89d9e3194aefd1e59d03292877046cabea88214bb33875f7c93b1939eab0f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page